# Researcher reports Android C2PA camera-signing forgery path

_Published Tuesday, August 25, 2026 at 10:17 PM EDT · Security, Products · Latest · Tier 2 — Notable_

Security researcher David Buchanan reported that Android C2PA camera applications relying on Key Attestation or Google Play Integrity can be induced to sign arbitrary media after a device is rooted through a privilege-escalation exploit or hardware fault attack. He said this could let forged images or videos carry camera-provenance signatures. Buchanan wrote that Google closed his report as infeasible to fix and awarded a $7,500 bounty, while a cited software exploit path could still be patched.

## Sources

- [da.vidbuchanan.co.uk](https://www.da.vidbuchanan.co.uk/blog/android-c2pa.html)

---
Canonical: https://techandbusiness.org/newswire/xD7wYNlh3BVMcvGc8PFC2V
Published: 2026-08-26T02:17:58.828Z
Story chronology: 2026-08-25T19:38:24.000Z
Retrieved: 2026-10-11T01:07:14.994Z
Publisher: Tech & Business (techandbusiness.org)
